Secure Client will ALWAYS attempt a TLS connection first. Once the TLS connection is up it will then concurrently attempt to form a DTLS connection and change over. If the DTLS connection fails, it will stay using the TLS connection.
This way the user is guaranteed to get a client VPN connection.
The questoin is then - what is causing the DTLS connection to fail. What kind of CPE are you connection from behind of? Have you checked them for firmware updates?
What happens if you use a different internet connection, such as mobile?